CertForums


Go Back   CertForums > Computing Support Forums > Security & Viruses


Sophos and false/positives issue

Reply
 
Thread Tools Display Modes
  #1  
Old 01-Jul-2009, 03:39 PM
dales's Avatar
dales dales is offline
Lifetime Member
Posts: 1,100
 
Reputation
Points: 871 dales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 points
Power: 26
Awards
None
Profile
Join Date: 12 Sep 2006
Location: Berkshire
Certifications: VCP,MCSA MCDST MCP A+ ITIL F
WIP: 70-680, other bits n bobs
Rep Power: 26
dales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 points
Sophos and false/positives issue

All,

We just received the latest update from sophos for our enterprise service, as it started rolling it out it became obvious that something was wrong. We have monitoring software installed on a number of pc's which monitor what applications are installed etc and that is proving a false/positive.

Also affected is the logmein client which I assume the dll that managements the heartbeat messages to logmein are being deleted.

There are a few other bits of software affected on our network by I think they are quite rare outside our network. But if you roll with sophos enterprise dont be surprised to get a bunch of false positives and random deletion of files.


Regards
Dale
www.dales-diary.co.uk
Twitter:dscriven
My linkedin Profile


Somewhere there's danger, somewhere there's injustice...and somewhere else the tea is getting cold.
 
Reply With Quote
  #2  
Old 01-Jul-2009, 03:47 PM
Gingerdave's Avatar
Gingerdave Gingerdave is offline
Longterm Member
Posts: 725
 
Reputation
Points: 1556 Gingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 points
Power: 26
Awards
None
Profile
Join Date: 03 Jul 2008
Location: Leeds
Age: 27
Certifications: AMCBS, A+, MCDST
WIP: 70-270, Mass Effect 2, Darwinia +
Rep Power: 26
Gingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 pointsGingerdave has over 1500 points
We had that with McAffee and dameware. We ended up configuring a new profile for the ou that contains the IT computers and then stoping the anti virus on the remote machine for the duration of the session.

 
Reply With Quote
  #3  
Old 03-Jul-2009, 12:08 PM
Pady Pady is offline
Registered Member
Posts: 87
 
Reputation
Points: 32 Pady has between 1 & 100 points
Power: 8
Awards
None
Profile
Join Date: 08 Dec 2005
Location: Nottingham UK
Age: 30
Certifications: A+, See Sig for HW Certs
WIP: Network+ & MCP 70-270
Rep Power: 8
Pady has between 1 & 100 points
you could also contact Sophos and advise them about these false positives. they are usually very quick to update their detection rules. this is what we did for several pieces of software our consultants use. worked out easier and quicker this way.



IBM/Lenovo - Mobile & Desktop Certified Engineer
Toshiba - Laptop Certified Engineer
HP - Desktop, Workstation and Notebook Certified Engineer/Laser Printer Certified Engineer
Dell - Desktop & Portables Certified Engineer
 
Reply With Quote
  #4  
Old 03-Jul-2009, 12:59 PM
dales's Avatar
dales dales is offline
Lifetime Member
Posts: 1,100
 
Reputation
Points: 871 dales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 points
Power: 26
Awards
None
Profile
Join Date: 12 Sep 2006
Location: Berkshire
Certifications: VCP,MCSA MCDST MCP A+ ITIL F
WIP: 70-680, other bits n bobs
Rep Power: 26
dales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 points
Yes we are doing that, I've supplied sophos with the files involved yesterday but thought I'd just post a quickie just in case anyone else starts getting them.

On one of our servers it started quarintining some pretty critical MS files.


Regards
Dale
www.dales-diary.co.uk
Twitter:dscriven
My linkedin Profile


Somewhere there's danger, somewhere there's injustice...and somewhere else the tea is getting cold.
 
Reply With Quote
Reply

Go Back   CertForums > Computing Support Forums > Security & Viruses

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 05:50 AM.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2009 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Lunarpages.com Web Hosting